Meta Out, OpenAI Halfway In, Google All In: The Supplier Map on the Day Brussels Started Issuing Fines

With the European AI Office authorized to fine GPAI since August 2, signing the Code of Practice has become a practical filter. Each instance of non-signature turns into a costly defense case by case.
The calendar counted down to the end on Sunday. Since August 2, the AI Office of the European Commission can formally demand information, request access to models, order remediation, and impose fines against suppliers of general-purpose models, with a ceiling of €15 million or 3% of global annual revenue. What was once diplomatic pressure is now procedural cost, and the GPAI Code of Practice, published by the Commission on July 10, 2025, ceases to be an invitation: it now operates as a presumption of compliance. Those who signed reduce the risk of investigation. Those who did not sign will have to prove, chapter by chapter, that they comply with the AI Act through equivalent means.
The list of signatories published by the AI Office includes 26 organizations and covers most of the market. Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Cohere, and Aleph Alpha adhered to all three chapters: Transparency, Copyright, and Security. OpenAI appeared on the registry but with a partial footprint: it signed the chapters on Transparency and Security but omitted the chapter on Copyright. Elon Musk's xAI went even further in its selectivity, accepting only the Security chapter. Meta is the only comparable major player entirely absent from the document.
The Three Bets in Play
The reading of Google, Anthropic, Microsoft, Amazon, and IBM is the most defensive. Signing the Code provides procedural safe harbor and treats the EU as an institutional customer rather than an adversary. It is the same playbook these firms used when the GDPR came into effect in 2018: accept the European standard, export the standard to the rest of the product, and avoid fragmenting the training pipelines.
OpenAI chose a conscious middle ground. By publishing its compliance statement at the end of July, it covered Transparency and Security while simply skipping the Copyright chapter, which requires a public summary of training data and a documented policy for using protected works. The company is currently in litigation with the New York Times, German academic publishers, and Getty Images, and signing a European document that sets public training policy could be used against it in a U.S. lawsuit. It’s the kind of gap that the Commission can formally investigate from now on.
Meta has opted for an outright fight. In July 2025, Joel Kaplan, the company's global affairs head, publicly argued that "the code introduces legal uncertainties for developers and includes measures that go far beyond the AI Act." The reading from Menlo Park is that the text of the Code overreaches the regulation and creates obligations through the backdoor. Brussels’ view is that the company is simply avoiding the inevitable to preserve Llama under broad commercial terms. Neither side is likely to yield in the short term, and the practical result is that any European procurement using Llama will have to assemble equivalent documentation to the Code on its own and assume the risk.
What the European CIO Needs to Read Differently Today
Model supply contracts, particularly those integrated via API into SaaS products, are no longer standard. The compliance clause with the AI Act must explicitly state whether the supplier subscribed to the Code, to which chapters, and how it demonstrates compliance in the unsigned chapters. For risk teams in banks like Deutsche Bank and ING, and in pharmaceuticals like Sanofi and Bayer, the difference between "full subscription" and "equivalent compliance" is the difference between a ten-page dossier and a two-year investigation. The Financial Conduct Authority in the UK has already indicated it will require equivalent standards for AI in local financial services, even with the country outside the AI Act, which in practice will force American suppliers to meet two parallel regimes.
The dynamic in the United States is the opposite and complicates the picture. Donald Trump's executive order on June 2 created a voluntary framework for labs to consult the federal government on "covered frontier models", but explicitly prohibits any mandatory licensing. The contrast with Brussels creates the scenario that big techs have avoided for years: each model now carries two contradictory regulatory obligations, one prescriptive in the EU and one consultative in the U.S., with doubled compliance costs.
The part that the headline does not capture is the most important for the corporate buyer. The Code of Practice is not law; it is a presumption of compliance. A supplier that has not signed can continue to sell but transfers to the customer the burden of demonstrating that the model complies with the AI Act. This is why the next contract renegotiation with Meta in Europe will be slower and more expensive than with Google. And this is why the list of 26 is, today, the most relevant document in AI procurement in the European corporate market.